Okta Verify now transfers third-party codes to a new iPhone over Bluetooth (what it means for MSPs)

Turn the "I got a new phone" ticket into a quick Bluetooth transfer. Codes move straight to the new iPhone, with nothing syncing through a personal cloud account.

Bottom Line Up Front

As of Okta Verify 9.70.0 for iOS, a user upgrading to a new iPhone can move their third-party TOTP and Device Access codes to the new device over Bluetooth, not just their native Okta Verify accounts. It's a local device-to-device transfer with no cloud sync—so for MSPs supporting a portfolio of clients, it means fewer manual re-enrollments and fewer "I got a new phone" tickets, with no loss of security posture.

Key Takeaways
  • Okta Verify can now transfer third-party TOTP accounts and Device Access codes to a new device over Bluetooth, in addition to the native Okta Verify accounts it already supported.
  • The expanded transfer is currently iOS-to-iOS only. Other platform combinations still move native Okta Verify accounts over Bluetooth, but not third-party or Device Access codes.
  • The transfer happens device-to-device with no cloud sync, so MSPs get faster new-phone setup without compromising a phishing-resistant security posture.

“I got a new phone” tickets

As an MSP supporting multiple SMB clients on Okta, you've handled this ticket more times than you can count: a user gets a new phone, and their authenticator is suddenly empty. Okta Verify accounts could already be moved, but every third-party code—GitHub, AWS, Google, and the rest—often had to be re-enrolled by hand, one service at a time. Multiply that across every client you support, each with its own set of users, and "new phone day" becomes a recurring drain on your service desk.

What changed in Okta Verify v9.70.0 for iOS

Okta Verify has supported device-to-device Bluetooth transfer of native Okta Verify accounts for a while. Version 9.70.0 for iOS expands that transfer to also include:

  • Third-party TOTP accounts – GitHub, AWS, Google, and similar services.

  • Device Access codes – used for desktop features like Okta Device Access and Platform SSO.

So a full iPhone-to-iPhone move can now bring across all three in a single pass, with no manual re-enrollment of each service.

Understanding the scope of the change

This expansion is iOS-to-iOS only. If either device is Android, macOS, or Windows, you can still transfer native Okta Verify accounts over Bluetooth, but not third-party TOTP or Device Access codes. Those still require the usual re-enrollment on non-iOS moves. Worth knowing before you set a client's expectations.

Why this fits the way we tell you to run MFA

Here's the part we like: the transfer happens directly between the two devices over Bluetooth—nothing syncs through a personal cloud account. That matters, because the reason Okta Verify doesn't offer consumer-style cloud backup is a deliberate security decision: keeping MFA secrets device-bound and out of personal Google, Apple, or Microsoft accounts that could be phished. This feature closes a real convenience gap without reopening that risk. You get the easier upgrade path and the enterprise-grade posture your security-conscious clients—and their auditors—expect.

What to do about it

Want help standardizing device-change workflows across every client from one console? Talk to an Okta-certified expert (who isn't in sales).

See ZeroTek in Action

See how the platform works for your specific use cases

No slides. No script. Our team will walk you through the platform on a 30-minute call and answer any questions you have about your specific use cases.

Talk to our team →
Featured Case Study
Element Technologies
Managed Service Provider · 50+ Okta orgs managed
Challenge

Element needed a repeatable way to deploy a consistent Okta baseline across dozens of clients without manual checklists.

Outcome

ZeroTek centralized management across clients. ZeroConfig standardized their baseline and cut tenant setup from hours to minutes.

22x
Faster to identify config drift
30%
YoY increase in managed users
See It Live

See how 100+ MSPs are building
high-margin identity practices

A 30-minute demo will show you exactly how ZeroTek fits your stack, your team, and your client base. No pressure. No prep required.